This site uses cookies for anonymized analytics. For more information or to change your cookie settings, view our Cookie Policy.

The world’s most used penetration testing framework

Knowledge is power, especially when it’s shared. A collaboration between the open source community and Rapid7, Metasploit helps security teams do more than just verify vulnerabilities, manage security assessments, and improve security awareness; it empowers and arms defenders to always stay one step (or two) ahead of the game.

Get Metasploit

Open Source




Commercial Support


Free Trial


Get visibility into your network with Rapid7's InsightVM
30-Day Trial

Recent Blog Posts

Fri Sep 17 2021

Metasploit Wrap-Up

New modules for Jira user enumeration, Git Remote Code execution via git-lfs, Geutebruck Camera post exploitation module, and unauthenticated RCE in elFinder PHP application...

Fri Sep 10 2021

Metasploit Wrap-Up

Confluence Server OGNL Injection Our own wvu along with Jang added a module that exploits an OGNL injection (CVE-2021-26804)in Atlassian Confluence's WebWork component to execute commands as the Tomcat user. CVE-2021-26804 is...

Fri Sep 03 2021

Metasploit Wrap-Up

A new SMB server implementation to support capturing NTLM hashes across SMBv2 and SMBv3, even with encrypted SMB traffic. Plus, exploits for eBPF, Git LFS, and Geutebruck IP cameras....

View More Metasploit Blog Posts

View All

Related Products & Projects


Rapid7’s solution for advanced vulnerability management analytics and reporting.

Free Trial


Rapid7’s incident detection and response solution unifying SIEM, EDR, and UBA capabilities.

Free Trial


Virtual machines full of intentional security vulnerabilities. Exploit at will!

Download Now